VendorsOrbisiuschild_theme_creatorall versions
Vulnerabilities

Orbisius Child Theme Creator

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2020-28649
The orbisius-child-theme-creator plugin before 1.5.2 for WordPress allows CSRF via orbisius_ctc_theme_editor_manage_file.
Published 2020-11-16 · Modified
8.8EPSS 0.008
CVE-2024-43276
WordPress Child Theme Creator by Orbisius plugin <= 1.5.4 - Cross Site Scripting (XSS) vulnerability
Published 2024-08-18 · Analyzed
7.1EPSS 0.003
CVE-2015-9456
The orbisius-child-theme-creator plugin before 1.2.8 for WordPress has incorrect access control for file modification via the wp-admin/admin-ajax.php?action=orbisius_ctc_theme_editor_ajax&sub_cmd=save_file theme_1, theme_1_file, or theme_1_file_contents parameter.
Published 2019-10-07 · Modified
6.5EPSS 0.014